The disclosed "move-on-push" gap detonated on iteration 16's route-table pattern: `push(self.routes, r)` moved the Route into the container while the `take r` parameter's scope-end DROP still fired — the container's own drop plan (multi_free) then freed the element a second time. ASan: SEGV in class_free during trap unwind; latent until now because pushed elements were Texts, which copy at the boundary (2026-08-14). owner.ml analyze_call: `push`'s value slot and `set`'s key/value slots now TRANSFER an Owned, non-copy-stored place (record_move, exactly the take-arg shape), so the pusher's drop disappears. Text/json.Value keep the copy-store path (stores_by_copy) and the caller still drops the fresh copy. Traced (gc) values remain exempt (tracing owns them). A user-declared push/set fn of the same name wins, per the builtin shadowing rule. Pinned by tests/corpus/run/container-owned-move (route table: interface- typed field values pushed via take params, dispatched by ICALL, mixed with Text pushes) — the exact iteration-16 shape, ASan-clean. Verified: woc-test 540/0; oop-e2e 88/0; log-watcher 7/0; employee 8/0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
4 lines
11 B
Text
4 lines
11 B
Text
101
|
|
8
|
|
-1
|
|
2
|